Hacker News new | ask | show | jobs
by Kozoxy 2801 days ago
That's great, but when are they going to properly address and mitigate the potentially massively lethal cyber- and national-security issues made possible by the tech?

Or do we have to talk only about what they want us to talk?

3 comments

Great, let's evaluate the deaths caused by regular cars. Lets evaluate risks posed by burning fossil fuels. Let's evaluate pretty much every single little detail about other auto brands and present our findings in a fashion where we can compare and rank best to worst. Having just done this I'm completely satisfied with Tesla's approach in comparison to what other brands have been doing.
Like what? Other car manufactures already do remote software updates.
People's safety isn't something to be iterated.

Any security patch will already come too late -- when it comes to cars, it must not have security problems to begin with.

The cybersecurity model just isn't safe for this. It's up to them to fix this, not me.

> People's safety isn't something to be iterated.

Look into the history of automotive safety to understand how ridiculous this sounds. Cars were total death traps for many, many decades.

"It must not have security problems to begin with"

No product is bulletproof from a security standpoint, and there's no way to make something bulletproof. What are you suggesting they do?

Tesla absolutely launched their over-the-air capabilities without sufficient planning. If you look at the early Keen Labs presentations[0] it's insane that it was launched the way it was. At least they added code signing later...

[0] https://www.blackhat.com/docs/us-17/thursday/us-17-Nie-Free-...

They did OTAs without code signing? That's an unprecedented level of incompetency! What were they thinking?
Everything has potential to cause issues, won't stop progress. Let's not act like they are ignoring this.
Do users have the ability to stop updates without repercussions?

Is it really a choice that cannot be overridden by the update?

If X declares war on California, will California shutdown every Tesla in X?

Will I be allowed to export my Tesla in 15 years to whatever developing country I like?

What?

Did you think before you typed because 2 of those questions have nothing to do with this.

Will my car be taken over and kill me?

Will other people's cars be taken over and kill me?

Will my car be taken over and be used to drive me to someone who will harm me?

These are life or death concerns and let's not act like they're not ignoring this.

1. No it wont, please show me where this is happening. 2. No it wont, please show me where this is happening. 3. No it wont, please show me where this is happening.

There's concerns and then crazy questions and comments.

So no one should try to prevent security flaws because that particular flaw hasn't happened and only fix them when they do?

The question shouldn't be "has it happened." The question should be how realistic is the chance of this happening in the future?

As if technology has never been held hostage before until a ransom is paid.

#1 is easy: “pay us or we will accelerate your car in a random direction in 24h”. The first round will be scareware, the future may not be.

#1 is easy: “pay us or we will accelerate your car in a random direction in 24h”. The first round will be scareware, the future may not be.

Can't happen in a tesla, “so even if somebody would gain access to the car, they cannot gain access to the powertrain or to the braking system.”

And how is this any different than we'll kill you in 24h if you dont pay?

How can that be? You can remotely update the system that does autopilot, and autopilot must have control over throttle/brake/steering.

Even shutting off the lights or disabling the wipers can create big problems.

That wasn't a question nor does anyone think you shouldn't try to prevent security flaws. The fact is it wont happen because of the way these systems are built within the car.

Security flaws will always exist but there are limits and just blatantly claiming we're all gonna die because tesla doesn't care about security is a joke.

Everything has potential to cause issues, and that's not reason to dismiss life or death concerns.

What are they doing about it that's effective? They are ignoring this.

No one is dismissing life or death concerns they are dismissing your comments.